Certificates from the cisco ucm, Dns lookup prerequisites, Cisco unified communications manager prerequisites – Cisco ASA 5505 User Manual

Page 989: Access list rules

Advertising
background image

48-7

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 48 Configuring the Cisco Phone Proxy

Prerequisites for the Phone Proxy

Certificates from the Cisco UCM

Import the following certificates which are stored on the Cisco UCM. These certificates are required by
the ASA for the phone proxy.

Cisco_Manufacturing_CA

CAP-RTP-001

CAP-RTP-002

CAPF certificate (Optional)

If LSC provisioning is required or you have LSC enabled IP phones, you must import the CAPF
certificate from the Cisco UCM. If the Cisco UCM has more than one CAPF certificate, you must import
all of them to the ASA.

Note

You can configure LSC provisioning for additional end-user authentication. See the Cisco Unified
Communications Manager configuration guide for information.

See

Importing Certificates from the Cisco UCM, page 48-15

. For example, the CA Manufacturer

certificate is required by the phone proxy to validate the IP phone certificate.

DNS Lookup Prerequisites

If you have an fully qualified domain name (FQDN) configured for the Cisco UCM rather than an
IP address, you must configure and enable DNS lookup on the ASA. For information about the dns
domain-lookup
command and how to use it to configure DNS lookup, see command reference.

After configuring the DNS lookup, make sure that the ASA can ping the Cisco UCM with the
configured FQDN.

You must configure DNS lookup when you have a CAPF service enabled and the Cisco UCM is not
running on the Publisher but the Publisher is configured with a FQDN instead of an IP address.

Cisco Unified Communications Manager Prerequisites

The TFTP server must reside on the same interface as the Cisco UCM.

The Cisco UCM can be on a private network on the inside but you need to have a static mapping for
the Cisco UCM on the ASA to a public routable address.

If NAT is required for Cisco UCM, it must be configured on the ASA, not on the existing firewall.

Access List Rules

If the phone proxy is deployed behind an existing firewall, access-list rules to permit signaling, TFTP
requests, and media traffic to the phone proxy must be configured.

If NAT is configured for the TFTP server or Cisco UCMs, the translated “global” address must be used
in the access lists.

Table 48-1

lists the ports that are required to be configured on the existing firewall:

Advertising